Compliance

State attorneys general are increasingly shaping the regulatory landscape for organizations that rely on technology, data and artificial intelligence. In the latest episode of Squire Patton Boggs’ Antitrust Amplified podcast, antitrust partner Lauren Briggerman sits down with representatives from the California Department of Justice and the District of Columbia Attorney General’s Office to discuss evolving…

As privacy regulation, AI governance, and cybersecurity requirements continue to evolve globally, members of Squire Patton Boggs’ Data Privacy, Cybersecurity & Digital Assets team will be speaking on legal developments at several upcoming webinars, conferences, and CLE programs. Explore the events and hot topics below. For many of these programs we can arrange free passes for clients and are noted below. We look forward to connecting with you!

Continue Reading Upcoming Speaking Engagements and CLE Opportunities with the SPB Data Team

As we flagged last month in our mid-year U.S. privacy roundup, the Delaware legislature recently passed House Bill 380 (“HB 380”), which amends the Delaware Personal Data Privacy Act (the “Act”) in ways that impose significant new, and in many ways complex and novel, requirements on controllers, processors and third parties.  On September 2, 2026, Delaware Governor Matt Meyer signed House Bill 380 into law and thus amended what was already a fairly strict state consumer privacy law. These amendments significantly lower the volume-based thresholds for applicability, create new obligations for providers of “reports” used to make certain types of decisions and businesses that use that data, add new requirements for consumer rights, impose restrictions on profiling job applicants, employees and independent contractors, and require contracts with and obligations from third parties that receive personal data (e.g., sales), among many other changes. These amendments will become effective on January 1, 2027.

Businesses that are subject to the Act (of which there will be many more as a result of HB 380) should carefully review the amended Act to determine their new obligations, including the significant amendments discussed below.  Financial institutions in particular should determine whether they must now comply with the Act, as the broad exemption for financial institutions subject to Title V of the Gramm-Leach-Bliley Act (the “GLBA”) has been replaced by a narrower exemption for only certain types of financial institutions and certain of their affiliates (see discussion below).

Continue Reading Amendments to Delaware’s Consumer Privacy Law Deepen the Morass of State Privacy Regulation

To harmonize cybersecurity requirements across the EU, the Cyber Resilience Act (CRA) applies to hardware and software products made available in the EU whose intended or reasonably foreseeable use involves a direct or indirect connection to a device or network. This includes software applications, Internet-of-Things (IoT) products, routers, connected machinery and separately marketed digital components…

Last week, a European Data Protection Authority imposed a substantial fine for a company’s use of an algorithmic system that automatically restricted individuals’ access to income-generating opportunities via an online platform and the failure to provide adequate transparency.  Accounts were deactivated where the system detected suspected fraud or low customer ratings and no human assessment…

2026 started with 20 state consumer privacy laws (SCPLs), three of which went into force on January 1, 2026. During the first half of 2026, four new SCPLs were added, bringing the count to 24 – all since the California legislature passed the California Consumer Privacy Act (CCPA) in June 2018. Also, during the first half of 2026, state legislatures enacted significant amendments to their existing SCPLs. We cover the state privacy laws developments in this first of a three-part series on mid-year US data law updates – stay tuned for updates on teen online privacy and safety, as well as AI.

Continue Reading Adding to the Count: The latest in state consumer privacy laws

On July 22, 2026, the Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers (the “Provisions”), which will take effect on September 1, 2026.

The Provisions are designed to reduce compliance burdens for smaller businesses, while maintaining baseline personal information protection requirements. They introduce a series of streamlined compliance measures for qualifying entities in China.

Continue Reading China Introduces Simplified Personal Information Protection Regime for Small-Scale Personal Information Handlers

The Guidelines 03/2026 on web scraping in the context of generative AI, adopted by the European Data Protection Board “EDPB” for public consultation on 7 July 2026, are notable not only for what they require but for what they acknowledge. The document is unusually candid about three limitations: an epistemic one (the controller may not always know what it has collected), a technical one (what a model has learned cannot, today, be easily unlearned), and an institutional one (some of the assessments woven into the GDPR analysis sit, at least in part, with other authorities and courts). These acknowledgements are welcome, and they distinguish the text from more declaratory guidance. The tension is that the requirements built on top of them are not always adjusted accordingly, and that gap, between what the EDPB admits and what it nonetheless requires, is where the most interesting questions of the consultation lie.

Briefly, the Guidelines cover scraping performed by private entities, whether carried out in-house, commissioned from a third party or effected through the acquisition of pre-scraped datasets. They work through the familiar sequence: allocation of controller and processor roles, the core principles of Article 5 GDPR (purpose limitation, transparency, minimization, accuracy), the choice of legal basis, with legitimate interest under Article 6(1)(f) GDPR treated as the realistic candidate and consent all but discarded, and the treatment of special categories of data incidentally swept up in the collection, for which the EDPB adapts the CJEU’s GC & Others framework. Little of this structure will surprise anyone who has followed the Board’s recent work on AI. What rewards attention is how each of these familiar steps is made to function once the three limitations above enter the analysis.

Continue Reading Regulating the Irreversible: The EDPB’S Web Scraping Guidelines and the Limits of GDPR Orthodoxy

The UK’s data protection framework continues to evolve following the enactment of the Data (Use and Access) Act 2025 (DUAA). One of the more operationally significant developments for organisations is the introduction of a new statutory right for individuals to complain to controllers regarding infringements of the UK General Data Protection Regulation (GDPR), as well as a framework governing how controllers must handle those complaints.

The relevant provisions will apply from 19 June 2026, pursuant to the Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026. On or before that date, organisations subject to the UK GDPR will need to update their privacy notices, and introduce formal data protection complaint handling processes that meet specific legal requirements.

Continue Reading The Data (Use and Access) Act 2025 and the new right for individuals to complain to controllers: What organisations need to do before 19 June 2026

French law requires that where hosting services providers host certain types of health data, they must first obtain certification as “hébergeurs de données de santé” (“HDS”) which translates as “health data hosting service providers”. The relevant HDS certification framework was updated in 2024. This framework notably incorporates the amendments introduced by the law of 21 May 2024 aimed at securing and regulating the digital space, as well the decree of 24 March 2026, which imposes data sovereignty-related obligations that will take effect in September 2026.

Continue Reading V2.0 Certification of French Health Data Hosting Service Providers (HDS) now Fully Effective